CVE-2026-23387
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe() devm_add_action_or_reset() already invokes the action on failure, so the explicit put causes a double-put.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/188ba3468cb7c098c62609d82e9fc58d29ead7f4Patch
- https://git.kernel.org/stable/c/1e0465139fd9caee7ffefe285ef7d5f21919e474Patch
- https://git.kernel.org/stable/c/95b14ecc56881dd9a187e1e84dd0daa88ff22c5dPatch
- https://git.kernel.org/stable/c/ea07fcfbba4301839db3784f09955d9fa3e98090Patch
- https://git.kernel.org/stable/c/fd5bed798f45eb3a178ad527b43ab92705faaf8aPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.